HollowFrame Loader and Matryoshka Malware Target Law Firm with Advanced Techniques

HollowFrame Loader and Matryoshka Malware Target Law Firm with Advanced Techniques

First seen 3 Aug 2026, 14:53 UTC ScworldInfosecurity-Magazineblackpointcyber.com 85% similarity 67.5

Article Content

Browse articles
ThreatCluster

A sophisticated cyberattack has been identified, targeting a law firm with a new Go-based loader named HollowFrame and a Rust-based malware family called Matryoshka. The attack commenced with a spear-phishing email leading to an encrypted archive containing a malicious Windows Shortcut file. Upon execution, the malware escalated privileges, disabled Microsoft Defender protections, and downloaded additional payloads. HollowFrame employs DLL sideloading techniques using a counterfeit Python runtime to evade detection. The Matryoshka backdoor features two variants, one utilizing HTTP and the other leveraging a private GitHub repository for command and control. The attack's modular design complicates detection and attribution, posing a significant threat to the affected organization. Blackpoint Cyber has recommended monitoring for unexpected GitHub API connections as part of their mitigation strategy.

Key Points: • The HollowFrame loader uses a fake Python DLL to bypass Microsoft Defender. • The attack targets a law firm, employing spear-phishing to initiate the intrusion. • Matryoshka malware features two variants, complicating detection and enhancing persistence.

ThreatCluster AI How this analysis works

Timeline

2026-07-30
Research on HollowFrame and Matryoshka published
Blackpoint Cyber released findings on the new loader and malware family, detailing their sophisticated attack methods.
Infosecurity-Magazine
Date unknown
Spear-phishing email sent to law firm
The attack began with a spear-phishing email targeting staff at the law firm, leading to the infection.
Scworld
Date unknown
Malware executed and Defender protections disabled
The executed shortcut file escalated privileges and disabled Microsoft Defender protections before downloading payloads.
Infosecurity-Magazine
Date unknown
DLL sideloading technique employed
HollowFrame utilized a counterfeit Python runtime to sideload malicious code, evading detection.
Scworld

Community

Browse all →